Aggregator
CVE-2025-39988 | Linux Kernel up to 5.15.193/6.1.154/6.6.108/6.12.49/6.16.9 etas_es58x ndo_change_mtu buffer overflow (Nessus ID 271561)
CVE-2025-39984 | Linux Kernel up to 6.12.49/6.16.9 net include/linux/skbuff.h skb_pp_cow_data use after free (Nessus ID 271562)
CVE-2025-39998 | Linux Kernel up to 6.6.109/6.12.50/6.16.10/6.17.0 scsi target_core_configfs.c snprintf return value (EUVD-2025-34575 / Nessus ID 271557)
CVE-2025-39981 | Linux Kernel up to 6.16.9 Bluetooth mgmt_pending use after free (Nessus ID 271563)
CVE-2025-39978 | Linux Kernel up to 6.1.154/6.6.108/6.12.49/6.16.9 octeontx2-pf otx2_tc_add_flow use after free (Nessus ID 271564)
PhantomCaptcha: Sophisticated Phishing Used to Hijack Aid Groups
The PhantomCaptcha operation proved to be one of the most sophisticated phishing campaigns of recent months, directed at
The post PhantomCaptcha: Sophisticated Phishing Used to Hijack Aid Groups appeared first on Penetration Testing Tools.
盖茨的核电公司通过环评
Mass Attack: Hackers Hit WordPress Plugins With 8.7M Exploits in 48 Hours
A widespread exploitation campaign has descended upon WordPress sites: attackers are targeting installations that use the GutenKit and
The post Mass Attack: Hackers Hit WordPress Plugins With 8.7M Exploits in 48 Hours appeared first on Penetration Testing Tools.
AI Sidebar Spoofing: New Attack Hides Phishing in Fake Browser Extensions
Researchers at SquareX have published a comprehensive report on a newly discovered vulnerability known as AI Sidebar Spoofing—a
The post AI Sidebar Spoofing: New Attack Hides Phishing in Fake Browser Extensions appeared first on Penetration Testing Tools.
DataCon2025报名启动:用数据,守护未来! (文末抽奖)
How We (Almost) Found Chromium's Bug via Crash Reports to Report URI
Tracking down bugs in software is a pain that all of us who write code must bear. When we're talking about outright errors in a web page, you typically have something to get you started (such as output in the console), but that wasn't the case
关于国家授时中心遭受美国国家安全局网络攻击事件的技术分析报告
【漏洞通告】Windows 服务器更新服务 (WSUS) 远程代码执行漏洞(CVE-2025-59287)
CVE-2025-11682 | Perx Customer Engagement & Loyalty Platform up to 4.617.3 LMT Dashboard cross site scripting
CVE-2025-12055 | MPDV Mikrolab MIP 2/FEDRA 2/HYDRA X Filename path traversal (EUVD-2025-36096)
Baohuo Backdoor Hijacks 58,000 Telegram X Accounts for Covert Takeover
The malicious modification of Telegram X, discovered by specialists at Doctor Web, turned out to be far more
The post Baohuo Backdoor Hijacks 58,000 Telegram X Accounts for Covert Takeover appeared first on Penetration Testing Tools.
上周关注度较高的产品安全漏洞(20251020-20251026)
CNVD漏洞周报2025年第41期
Agenda Ransomware Deploys Linux Variant on Windows for Stealth Attack
Trend Research has detailed a new wave of attacks carried out by the Agenda ransomware group, which has
The post Agenda Ransomware Deploys Linux Variant on Windows for Stealth Attack appeared first on Penetration Testing Tools.